diff --git a/.gitea/workflows/build.yml b/.gitea/workflows/build.yml index abef039..076db0f 100644 --- a/.gitea/workflows/build.yml +++ b/.gitea/workflows/build.yml @@ -1,4 +1,3 @@ - name: Build container image on: @@ -51,6 +50,7 @@ jobs: AUTH_BASE64: ${{ secrets.READONLY_AUTH_BASE64 }} run: | set -euo pipefail + sed "s|READONLY_TOKEN_PLACEHOLDER|${AUTH_BASE64}|g" \ configs/auth.json.template > configs/auth.json @@ -95,14 +95,32 @@ jobs: context: . file: ./Containerfile platforms: linux/amd64 - push: ${{ github.event_name != 'pull_request' }} tags: ${{ steps.metadata.outputs.tags }} labels: ${{ steps.metadata.outputs.labels }} + + pull: true + oci-mediatypes: true compression: zstd + provenance: false sbom: false + cache-from: ${{ github.event_name != 'pull_request' && format('type=registry,ref={0}/{1}:buildcache-amd64-main', env.IMAGE_REGISTRY, env.IMAGE_NAME) || '' }} + cache-to: ${{ github.event_name != 'pull_request' && format('type=registry,ref={0}/{1}:buildcache-amd64-main,mode=max', env.IMAGE_REGISTRY, env.IMAGE_NAME) || '' }} + + build-args: | + BUILDKIT_OCI_MEDIATYPE=true + + outputs: ${{ github.event_name != 'pull_request' && format('type=registry,push=true,oci-mediatypes=true,compression=zstd,compression-args=binary-path=/usr/bin/go-zstd-chunked') || '' }} + + - name: Install gettext dependencies + if: github.event_name != 'pull_request' && github.ref_name == 'main' + run: | + set -euo pipefail + sudo apt-get update + sudo apt-get install -y gettext + - name: Install Cosign if: github.event_name != 'pull_request' && github.ref_name == 'main' uses: sigstore/cosign-installer@v4.1.2 @@ -150,4 +168,4 @@ jobs: if: always() run: | rm -f configs/auth.json - docker buildx prune -a -f || true + docker buildx prune -a -f || true \ No newline at end of file